PkgRadar

PyPI · pypi.org

entro-scan

Remote Payload: matched "curl "

Why PkgRadar flagged 1.2.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · entro_scan-1.2.4/entro_scan/ai.py
mediumCredential file accessmatched "GITHUB_TOKEN" · entro_scan-1.2.4/entro_scan/cli.py
mediumCredential file accessmatched "github_token" · entro_scan-1.2.4/entro_scan/github.py

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.4Review372026-05-28
1.2.3Review372026-05-28
1.2.2Review372026-05-28
1.2.1Review372026-05-28
1.2.0Review372026-05-28
1.0.0Review102026-05-28

Block this in CI

PkgRadar gates entro-scan (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi entro-scan==1.2.4